Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README instructs users to obtain and configure API Keys for external MCP services but provides no guidance on protecting those credentials, such as avoiding pasting keys into shared chat contexts, committing them to repositories, or exposing them in client logs/screenshots. In a skill that depends on third-party service connectivity, this omission increases the risk of accidental credential leakage and downstream unauthorized access to the PatSnap account or associated data/services.
